After continuing to see new tools emerging, which rely on extracting the NTDLL syscall IDs from "mov eax, X" instruction, I wanted to remind everyone that syscall IDs can easily be calculated by sorting the addresses of Nt*/Zw* functions in NTDLL from lowest to highest. ๐Ÿป
7
63
1
278
This tweet is unavailable
Sounds like it may be much less complicated ๐Ÿ˜›

Jan 10, 2023 ยท 9:24 PM UTC

3